# Watcher errors on sending report with attachment (Error 500)

**URL:** <https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [February 2, 2018, 12:05am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127 "2018-02-02T00:05:09Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![cafuego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cafuego/32/25146_2.png) [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Post date:** [February 2, 2018, 12:05am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/1 "2018-02-02T00:05:09Z")

</div>

I use version 5.6.5 of the ELK stack, running under docker.

I have a watch that is supposed to run once per month on the 1st of the month and send an email with a PDF report attached containing stats for the previous month.

When I simulate the watch via the Kibana UI, it works and I receive an email with an attachment that contains the correct dashboard data.

However, when the watch triggers on the 1st of the month, I receive no email and the only log entry I can find is in my kibana.log, telling me "statusCode": 500".

I've diffed the kibana log entries for the successful manual report generation and the failed automagic watcher generation and apart from the status code and time stamp/duration, they are identical.

Where do I go next to try and find out what is causing this 500 error on the automagic run?

I've added the watch config, 200 reponse and 500 response at [https://pastebin.com/EL6qZr7E](https://pastebin.com/EL6qZr7E)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 7, 2018, 8:56am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/2 "2018-02-07T08:56:14Z")

</div>

Hey,

each watch run creates a so called watch history entry to check out what happened, you can query for those like this

```auto
GET .watcher-history-6-*/_search
{
  "query": {
    "bool": {
      "filter": {
        "term": {
          "watch_id": "YOUR_WATCH_ID"
        }
      }
    }
  }
}

```

Thanks!

---

<div class="post-metadata">

**Author:** ![cafuego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cafuego/32/25146_2.png) [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Post date:** [February 8, 2018, 5:11am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/3 "2018-02-08T05:11:31Z")

</div>

Thanks - but that only gives me the same information that's logged with the watch; in this case:

`"reason": "Watch[WATCH_ID] attachment[api_metric.pdf] HTTP error status host[kibana], port[5601], method[POST], path[/api/reporting/generate/printablePdf], status[500]"`

but I already knew that, it's what made me go look at the kibana log.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 8, 2018, 8:02am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/4 "2018-02-08T08:02:00Z")

</div>

hey,

I think the PDF link you provided may not be the correct one. The documentation shows a direct link to the dashboard, where as you are calling the generatePDF URL. Can you try to specify the dashboard, like done in the docs linking to the dashboard?

--Alex

---

<div class="post-metadata">

**Author:** ![cafuego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cafuego/32/25146_2.png) [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Post date:** [February 9, 2018, 4:38am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/5 "2018-02-09T04:38:37Z")

</div>

The URL reported in the error is only the path; the full URL is the one I copied from the Dashboard \> Reporting \> Generation URL. The rest of the URL is parsed by the watch config and ends up in `"params": { "jobParams" }` in the config (it's in the pastebin).

The job only errors when it's run by a watch on the timer, when I kick it off manual via Simulate (with identical settings) it works fine.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 9, 2018, 2:45pm UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/6 "2018-02-09T14:45:37Z")

</div>

duh. I have misread your initial watch. We changed the mechanism how to retrieve a dashboard a long time ago, from sync to a polling based mechanism.

This also requires you to use the `reporting` email attachment action. Can you replace the one you are using right now with the `reporting` one?

[https://www.elastic.co/guide/en/x-pack/6.2/actions-email.html#configuring-email-attachments](https://www.elastic.co/guide/en/x-pack/6.2/actions-email.html#configuring-email-attachments)

--Alex

---

<div class="post-metadata">

**Author:** ![cafuego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cafuego/32/25146_2.png) [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Post date:** [February 12, 2018, 7:55am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/7 "2018-02-12T07:55:54Z")

</div>

Yay, that seems to have done the trick - thanks Alex!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 12, 2018, 9:00am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/8 "2018-02-12T09:00:07Z")

</div>

Hey,

great you got it working finally!

Is there anything we can improve our docs on, so that this is more obvious you should use the `reporting` action for this task? Would love to get some feedback here, so others dont fall into the same trap.

--Alex

---

<div class="post-metadata">

**Author:** ![cafuego](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cafuego/32/25146_2.png) [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Post date:** [February 12, 2018, 9:47pm UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/9 "2018-02-12T21:47:43Z")

</div>

I'm not 100% sure - I originally set up this watch a good 6 months ago or so. I found an example on the ES docs site and customised that, but I cannot for the life of me find that example again :-/

Probably the easiest way to stop the trap is to add a little validator on the watch save form; make it pop up an error that mentions "Use reporting instead". From there a docs search should've probably seen me sorted 🙂

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 14, 2018, 7:47am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/10 "2018-02-14T07:47:46Z")

</div>

Ah, that probably explains it, we changed how we did things regarding report generation from 2.4 to 5.0, so maybe you ran into that?

Thanks for all the patience!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2018, 7:47am UTC](https://discuss.elastic.co/t/watcher-errors-on-sending-report-with-attachment-error-500/118127/11 "2018-03-14T07:47:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
